product-owner

Pass

Audited by Gen Agent Trust Hub on Mar 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the bd CLI tool and local bash scripts (e.g., scripts/spawn-agents.sh) to manage feature tasks and agent processes. These actions are performed within the local project context to facilitate the development workflow.- [PROMPT_INJECTION]: The skill ingests user requirements and incorporates them into task descriptions and shell commands. This creates a surface for indirect prompt injection; however, the instruction to utilize a multi-step brainstorming and approval process before task creation serves as a functional mitigation strategy.- [SAFE]: Analysis of the skill instructions and code patterns revealed no evidence of remote code execution, obfuscation, persistence mechanisms, or unauthorized data exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 24, 2026, 06:05 PM